IP.Board SQL Injection
Invision Power Board (IPB) is a professional forum system that has been built from the ground up with speed and security in mind, taking advantage of object oriented code, highly-optimized SQL queries, and the fast PHP engine. A comprehensive administration control panel is included to help you keep your board running smoothly. Moderators will also enjoy the full range of options available to them via built-in tools and moderators control panel. Members will appreciate the ability to subscribe to topics, send private messages, and perform a host of other options through the user control panel. It is used by millions of people over the world. There are three problems related to this vulnerability. The first causes an SQL error by tampering with the offset in the 'sources/Memberlist.php' feature. The same issue is also present in the 'sources/Online.php' file. The other problem is that it is easy for an attacker to learn the full physical path of the webserver. This can be accomplished via the 'Change Personal Photo' option in the user control panel.